[Security] Bump ActiveMQ from 5.14.5 to 5.19.2 (fixes CVE-2023-46604)#37944
[Security] Bump ActiveMQ from 5.14.5 to 5.19.2 (fixes CVE-2023-46604)#37944Abacn merged 1 commit intoapache:masterfrom
Conversation
Fixes CVE-2023-46604 (CVSS 10.0, RCE via OpenWire protocol) and CVE-2022-41678 (CVSS 8.8, RCE via Jolokia and REST API). ActiveMQ is used exclusively as a test dependency in Beam (embedded broker for JMS, MQTT, and AMQP IO connector tests). Changes required for compatibility: - Upgrade JMS spec from 1.1 to 2.0 (geronimo-jms) for JMS IO, since ActiveMQ 5.19.x uses JMS 2.0 API (setJMSDeliveryTime). - Add JMS 2.0 createContext() stubs to MockNonSerializableConnectionFactory. - Exclude transitive proton-j from activemq-amqp in AMQP IO to avoid conflict with the directly declared proton-j:0.16.0. All three affected test modules pass: JMS IO, MQTT IO, AMQP IO. Fixes apache#37943
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request significantly enhances the project's security by upgrading the ActiveMQ test dependency to a version that remediates critical vulnerabilities. The upgrade necessitated minor compatibility adjustments in related modules, primarily involving an update to the JMS specification and resolution of a transitive dependency conflict. Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
|
Assigning reviewers: R: @Abacn for label java. Note: If you would like to opt out of this review, comment Available commands:
The PR bot will only process comments in the main thread (not review comments). |
Summary
Upgrades ActiveMQ from 5.14.5 to 5.19.2 to remediate critical security vulnerabilities. ActiveMQ is used exclusively as a test dependency in Beam (embedded broker for JMS, MQTT, and AMQP IO connector tests).
CVEs Fixed
Changes Required for Compatibility
geronimo-jms_1.1_spec:1.1.1→geronimo-jms_2.0_spec:1.0-alpha-2setJMSDeliveryTime). JMS 2.0 is fully backward-compatible with JMS 1.1 — only adds new methods.createContext()stubs.proton-j:0.34.1fromactivemq-amqpto avoid conflict with the directly declaredproton-j:0.16.0.Testing
All three affected test modules pass locally:
:sdks:java:io:jms:test(54 tests):sdks:java:io:mqtt:test:sdks:java:io:amqp:testFixes #37943
Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:
addresses #123), if applicable. This will automatically add a link to the pull request in the issue. If you would like the issue to automatically close on merging the pull request, commentfixes #<ISSUE NUMBER>instead.CHANGES.mdwith noteworthy changes.See the Contributor Guide for more tips on how to make review process smoother.
To check the build health, please visit https://github.com/apache/beam/blob/master/.test-infra/BUILD_STATUS.md
GitHub Actions Tests Status (on master branch)
See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.